35
recon / OSINT [Open Source Intelligence] TRAVERSING DOWN THE RABBIT HOLE Eric Hart -- Credit Suisse

recon / OSINT [Open Source Intelligence]Oxford Handbook of Naonal Security Intelligence The Tao of Open Source Intelligence Infosec InsMtute osinuramework.com owasp.org digital-forensics.sans.org

  • Upload
    others

  • View
    20

  • Download
    1

Embed Size (px)

Citation preview

Page 1: recon / OSINT [Open Source Intelligence]Oxford Handbook of Naonal Security Intelligence The Tao of Open Source Intelligence Infosec InsMtute osinuramework.com owasp.org digital-forensics.sans.org

recon/OSINT[OpenSourceIntelligence]

TRAVERSINGDOWNTHERABBITHOLE

EricHart--CreditSuisse

Page 2: recon / OSINT [Open Source Intelligence]Oxford Handbook of Naonal Security Intelligence The Tao of Open Source Intelligence Infosec InsMtute osinuramework.com owasp.org digital-forensics.sans.org

INTELLIGENCEGATHERINGANDRECONNAISSANCE

Ifyoudon’tknowwhereyou’regoinganyroadwillgetyouthere.

EricHart--CreditSuisse

Page 3: recon / OSINT [Open Source Intelligence]Oxford Handbook of Naonal Security Intelligence The Tao of Open Source Intelligence Infosec InsMtute osinuramework.com owasp.org digital-forensics.sans.org

ManyCommuniMes|OnePurpose

•  Governments

•  IntelligenceCommuniMes

•  ArmedForces

•  HomelandSecurity

•  LawEnforcementAgencies

•  Businesses

EricHart--CreditSuisse

Page 4: recon / OSINT [Open Source Intelligence]Oxford Handbook of Naonal Security Intelligence The Tao of Open Source Intelligence Infosec InsMtute osinuramework.com owasp.org digital-forensics.sans.org

ManyGoals|OnePurpose•  GatherasmuchinformaMonaspossiblefromallavailablesourcesandanalyzingittodoonething:

• ProduceAc*onableIntelligence*

EricHart--CreditSuisse

*pentest-standard.org

Page 5: recon / OSINT [Open Source Intelligence]Oxford Handbook of Naonal Security Intelligence The Tao of Open Source Intelligence Infosec InsMtute osinuramework.com owasp.org digital-forensics.sans.org

AllroadsleadtoNirvana…ordothey?

EricHart--CreditSuisse

Page 6: recon / OSINT [Open Source Intelligence]Oxford Handbook of Naonal Security Intelligence The Tao of Open Source Intelligence Infosec InsMtute osinuramework.com owasp.org digital-forensics.sans.org

INTELLIGENCETHEORY

•  IntelligenceistheulMmateparadox

•  AssumpMonsmustbeexplicit

•  Intelligencecanproducebenefitsandcanalsobeharmful

•  Intelligencecannotbepredicted,onlyrecommended

•  Intelligencecanproduceunintendedoutcomes

OxfordHandbookofNaMonalSecurityIntelligence–Dr.PeterGill

EricHart--CreditSuisse

Page 7: recon / OSINT [Open Source Intelligence]Oxford Handbook of Naonal Security Intelligence The Tao of Open Source Intelligence Infosec InsMtute osinuramework.com owasp.org digital-forensics.sans.org

INTELLIGENCETHEORY

•  TheCriMcalRealistApproach•  CausaMonthroughinteracMonbetweenactorsandstructures•  Processescannotbeobserved•  Evidenceshouldbetestedagainstthehypotheses|applicaMonofalternaMvetheoriesandmodels

OxfordHandbookofNaMonalSecurityIntelligence-PeterGill

EricHart--CreditSuisse

Page 8: recon / OSINT [Open Source Intelligence]Oxford Handbook of Naonal Security Intelligence The Tao of Open Source Intelligence Infosec InsMtute osinuramework.com owasp.org digital-forensics.sans.org

INTELLIGENCETHEORY

•  Intelligenceisasubsetofsurveillance•  Theheartofriskmanagementcombinesknowledgeandpower

EricHart--CreditSuisse

IntelligenceAc*vi*esTargeMngCollecMonAnalysisDisseminaMonAcMon

POWER

OxfordHandbookofNaMonalSecurityIntelligence-PeterGill

Page 9: recon / OSINT [Open Source Intelligence]Oxford Handbook of Naonal Security Intelligence The Tao of Open Source Intelligence Infosec InsMtute osinuramework.com owasp.org digital-forensics.sans.org

INTELLIGENCETHEORY

•  DefensiveSurveillancevsIntelligence

•  DefensiveSurveillance=Risk•  Intelligence=Threats

EricHart--CreditSuisse

OxfordHandbookofNaMonalSecurityIntelligence-PeterGill

Page 10: recon / OSINT [Open Source Intelligence]Oxford Handbook of Naonal Security Intelligence The Tao of Open Source Intelligence Infosec InsMtute osinuramework.com owasp.org digital-forensics.sans.org

INTELLIGENCETHEORY

•  FourTypesofKnowledgeandPower

•  Certainty–outcomesareknown,clarityofpreferenceisneeded•  Risk–benefitsandadverseeffectsareknown,probabilityofvariousoutcomes

•  Uncertainty–Possibleoutcomesareknown,nowaytoesMmateprobability

•  Ignorance–cannotanMcipateadverseeffects,magnitude,relevanceandprobabilityareunknown

EricHart--CreditSuisse

OxfordHandbookofNaMonalSecurityIntelligence-PeterGill

KNOWLEDGE

POWER

Page 11: recon / OSINT [Open Source Intelligence]Oxford Handbook of Naonal Security Intelligence The Tao of Open Source Intelligence Infosec InsMtute osinuramework.com owasp.org digital-forensics.sans.org

INTELLIGENCETHEORY

•  WhatisIntelligenceorOSINT?•  [Art+Craa+Science+Capability(read:DomainKnowledge]–RichardsJ.Heuer

TheTaoofOpenSourceIntelligence–StewartK.Bertram

EricHart--CreditSuisse

Page 12: recon / OSINT [Open Source Intelligence]Oxford Handbook of Naonal Security Intelligence The Tao of Open Source Intelligence Infosec InsMtute osinuramework.com owasp.org digital-forensics.sans.org

•  OSINT|FourconceptsorFourLayeredApproach

•  MulMlayered

•  Cybergeography•  MixedMedium

•  Tangibility

EricHart--CreditSuisse

INTELLIGENCETHEORYTheTaoofOpenSourceIntelligence–StewartK.Bertram

Page 13: recon / OSINT [Open Source Intelligence]Oxford Handbook of Naonal Security Intelligence The Tao of Open Source Intelligence Infosec InsMtute osinuramework.com owasp.org digital-forensics.sans.org

•  MulMlayered•  SurfaceWeb

•  CommonKnowledge**caveatemptor–GoogleisNOTtheinternet•  GenerallynotsensiMvedata•  Availableviamainstreambrowsers

•  DeepWeb•  Notindexedbymainsearchengines•  CannotbereadbyconvenMonaltechnology•  InformaMononindividualsislocatedherebutnoteasilyaccessible

•  DarkWeb•  Accessedbyanonymizedmethods(TOR)•  OaenusedforcriminalacMviMes

EricHart--CreditSuisse

INTELLIGENCETHEORYTheTaoofOpenSourceIntelligence–StewartK.Bertram

Page 14: recon / OSINT [Open Source Intelligence]Oxford Handbook of Naonal Security Intelligence The Tao of Open Source Intelligence Infosec InsMtute osinuramework.com owasp.org digital-forensics.sans.org

•  CyberGeography•  Regionbased

•  Anglophone•  Russophone•  Etc.

•  DividedlinguisMcally•  Knowingonlyonelanguagediminishessuccess

•  Beware‘single-sourceintelligence’

EricHart--CreditSuisse

INTELLIGENCETHEORYTheTaoofOpenSourceIntelligence–StewartK.Bertram

Page 15: recon / OSINT [Open Source Intelligence]Oxford Handbook of Naonal Security Intelligence The Tao of Open Source Intelligence Infosec InsMtute osinuramework.com owasp.org digital-forensics.sans.org

•  MixedMedium•  Notsingle-sourced•  ComplexcombinaMonofsearchanddisplaytechnologies

•  Eachcomponentrequiresauniquesetoftechniquestomaster

•  RisksandoperaMonalrequirementsmustbeevaluatedbeforebeingputintouse

EricHart--CreditSuisse

INTELLIGENCETHEORYTheTaoofOpenSourceIntelligence–StewartK.Bertram

Page 16: recon / OSINT [Open Source Intelligence]Oxford Handbook of Naonal Security Intelligence The Tao of Open Source Intelligence Infosec InsMtute osinuramework.com owasp.org digital-forensics.sans.org

•  Tangibility•  ‘Realworld’vstheInternet•  Importancetothehumanexperience?•  Relevancetobasicneeds,eg.stableelectricityandcleanwater

EricHart--CreditSuisse

INTELLIGENCETHEORYTheTaoofOpenSourceIntelligence–StewartK.Bertram

Page 17: recon / OSINT [Open Source Intelligence]Oxford Handbook of Naonal Security Intelligence The Tao of Open Source Intelligence Infosec InsMtute osinuramework.com owasp.org digital-forensics.sans.org

ELEMENTSOFOSINT

• OSINT–4Elements• Uncovering• DiscriminaMon• Refining• Delivering

InfosecInsMtute

EricHart--CreditSuisse

4Elements|SMllonepurpose:ProduceAcMonableIntelligence

Page 18: recon / OSINT [Open Source Intelligence]Oxford Handbook of Naonal Security Intelligence The Tao of Open Source Intelligence Infosec InsMtute osinuramework.com owasp.org digital-forensics.sans.org

ELEMENTSOFOSINT

• OSINT–Uncovering• Whoknowsaboutthedata?• Wheredowelook?• Whichdataisappropriate• LeveragedistributedexperMseandknowledge

InfosecInsMtute

EricHart--CreditSuisse

Page 19: recon / OSINT [Open Source Intelligence]Oxford Handbook of Naonal Security Intelligence The Tao of Open Source Intelligence Infosec InsMtute osinuramework.com owasp.org digital-forensics.sans.org

ELEMENTSOFOSINT

• OSINT–DiscriminaMon• Disseminatebetweenthegoodandthebad• Eliminatetheoutdatedandirrelevant

InfosecInsMtute

EricHart--CreditSuisse

Page 20: recon / OSINT [Open Source Intelligence]Oxford Handbook of Naonal Security Intelligence The Tao of Open Source Intelligence Infosec InsMtute osinuramework.com owasp.org digital-forensics.sans.org

ELEMENTSOFOSINT

• OSINT–Refining• Assemblingthefinaloutput• Lengthdependsuponrelevantdata

InfosecInsMtute

EricHart--CreditSuisse

Page 21: recon / OSINT [Open Source Intelligence]Oxford Handbook of Naonal Security Intelligence The Tao of Open Source Intelligence Infosec InsMtute osinuramework.com owasp.org digital-forensics.sans.org

ELEMENTSOFOSINT

• OSINT–Delivery• MustbegiveninproperMme• Formathastobeclearandeasilyunderstandable

InfosecInsMtute

EricHart--CreditSuisse

Page 22: recon / OSINT [Open Source Intelligence]Oxford Handbook of Naonal Security Intelligence The Tao of Open Source Intelligence Infosec InsMtute osinuramework.com owasp.org digital-forensics.sans.org

ELEMENTSOFOSINT •  OSINT–amaturitymodel•  Corporate•  Individual•  CovertGathering•  FootprinMng•  IdenMfyProtecMonMechanisms

•  3LevelsofInformaMonGathering•  Level1|Compliance•  Level2|BestPracMce•  Level3|StateSponsored

www.pentest-standard.org

EricHart--CreditSuisse

Page 23: recon / OSINT [Open Source Intelligence]Oxford Handbook of Naonal Security Intelligence The Tao of Open Source Intelligence Infosec InsMtute osinuramework.com owasp.org digital-forensics.sans.org

OSINTFRAMEWORK

EricHart--CreditSuisseEricHart--CreditSuisse

Page 24: recon / OSINT [Open Source Intelligence]Oxford Handbook of Naonal Security Intelligence The Tao of Open Source Intelligence Infosec InsMtute osinuramework.com owasp.org digital-forensics.sans.org

ELEMENTSOFOSINT

•  OWASP–TesMngFrameworkPhase1:BeforeDevelopmentBeginsPhase2:DuringDefiniMonandDesignPhase3:DuringDevelopmentPhase4:DuringDeploymentPhase5:MaintenanceandOperaMons

www.owasp.org

EricHart--CreditSuisse

Page 25: recon / OSINT [Open Source Intelligence]Oxford Handbook of Naonal Security Intelligence The Tao of Open Source Intelligence Infosec InsMtute osinuramework.com owasp.org digital-forensics.sans.org

ELEMENTSOFOSINT

•  OWASP–TesMngFrameworkPhase1:BeforeDevelopmentBegins1.1:DefineaSDLC1.2:ReviewPoliciesandStandards1.3:DevelopMeasurementandMetricsCriteriaandEnsureTraceability

www.owasp.org

EricHart--CreditSuisse

Page 26: recon / OSINT [Open Source Intelligence]Oxford Handbook of Naonal Security Intelligence The Tao of Open Source Intelligence Infosec InsMtute osinuramework.com owasp.org digital-forensics.sans.org

ELEMENTSOFOSINT

•  OWASP–TesMngFrameworkPhase2:DuringDefiniMonandDesign2.1:ReviewSecurityRequirements2.2:ReviewDesignandArchitecture2.3:CreateandReviewUMLModels2.4:CreateandReviewThreatModels

www.owasp.org

EricHart--CreditSuisse

Page 27: recon / OSINT [Open Source Intelligence]Oxford Handbook of Naonal Security Intelligence The Tao of Open Source Intelligence Infosec InsMtute osinuramework.com owasp.org digital-forensics.sans.org

ELEMENTSOFOSINT

•  OWASP–TesMngFrameworkPhase3:DuringDevelopment3.1:CodeWalkThrough3.2:CodeReviews

www.owasp.org

EricHart--CreditSuisse

Page 28: recon / OSINT [Open Source Intelligence]Oxford Handbook of Naonal Security Intelligence The Tao of Open Source Intelligence Infosec InsMtute osinuramework.com owasp.org digital-forensics.sans.org

ELEMENTSOFOSINT

•  OWASP–TesMngFrameworkPhase4:DuringDevelopment4.1:ApplicaMonPenetraMonTesMng4.2:ConfiguraMonManagementTesMng

www.owasp.org

EricHart--CreditSuisse

Page 29: recon / OSINT [Open Source Intelligence]Oxford Handbook of Naonal Security Intelligence The Tao of Open Source Intelligence Infosec InsMtute osinuramework.com owasp.org digital-forensics.sans.org

ELEMENTSOFOSINT

•  OWASP–TesMngFrameworkPhase5:MaintenanceandOperaMons5.1:OperaMonalManagementReviews5.2:PeriodicHealthChecks5.3:EnsureChangeVerificaMon

www.owasp.org

EricHart--CreditSuisse

Page 30: recon / OSINT [Open Source Intelligence]Oxford Handbook of Naonal Security Intelligence The Tao of Open Source Intelligence Infosec InsMtute osinuramework.com owasp.org digital-forensics.sans.org

ELEMENTSOFOSINTdigital-forensics.sans.org

EricHart--CreditSuisse

IPAddresses

DomainNames

Network/HostArMfacts

Tools

TTPs Tough!

Challenging

Annoying

Easy

Trivial

CollecMveIntelligenceFramework

collecMveintel.net•  REN-ISACproject•  PullsinfeedofIOC’sfrompublicandprivatesources

•  Focusesonlowerendof“pyramidofpain”•  Exportsdatatoinfrastructureorsupportslookupduringresponse

Page 31: recon / OSINT [Open Source Intelligence]Oxford Handbook of Naonal Security Intelligence The Tao of Open Source Intelligence Infosec InsMtute osinuramework.com owasp.org digital-forensics.sans.org

EricHart--CreditSuisse

FrameworkandMethodologyComparison ProgramObjec*vesUsedforComparisonCriteria

FrameworkorMethodology

SponsoringOrganiza*on

ProgramStructure ControlBaseline RiskTriage RiskBusinessCase

COBIT5 ISACA 4 2 0 0DSS PCI 0 2 0 0FAIR TheOpenGroup 0 0 2 4IRAM2 ISF 3 0 2 2ISO27000x ISO 4 1 0 0ISO31000 ISO 2 0 0 0SANS-20 CSC 0 3 0 0SP800-30 NIST 2 4 2 2SP800-53 NIST 1 4 1 0UCF UnifiedCompliance 0 3 0 0

HarveyBallfillpercentageindicatesrelaMvestrengthwithineachprogramobjecMvefromnone(0)tostrong(4).

GartnerResearch

Page 32: recon / OSINT [Open Source Intelligence]Oxford Handbook of Naonal Security Intelligence The Tao of Open Source Intelligence Infosec InsMtute osinuramework.com owasp.org digital-forensics.sans.org

AFrameworkisjustaguideline SoisOSINT

EricHart--CreditSuisse

!

Page 33: recon / OSINT [Open Source Intelligence]Oxford Handbook of Naonal Security Intelligence The Tao of Open Source Intelligence Infosec InsMtute osinuramework.com owasp.org digital-forensics.sans.org

APPENDIX

Sources:pentest-standard.orgOxfordHandbookofNaMonalSecurityIntelligenceTheTaoofOpenSourceIntelligenceInfosecInsMtuteosinuramework.comowasp.orgdigital-forensics.sans.orgverizon.comDavidJ.BlancoGartnerResearch EricHart--CreditSuisse

Page 34: recon / OSINT [Open Source Intelligence]Oxford Handbook of Naonal Security Intelligence The Tao of Open Source Intelligence Infosec InsMtute osinuramework.com owasp.org digital-forensics.sans.org

QUIZ

EricHart--CreditSuisse

•  NamethefirsttwoofficialintelligenceagenciesformedintheUS?

•  InwhatyearwastheCIAfirstformed?•  WhenwasGaryPowersshotdown?•  WhichTCPportishackedmostoaen?•  Windows8isa_____ringprocessmodeoperaMngsystem?

•  Namethem•  WhichofthefollowingismostcommonlyusedtodisableDEPin

Windows7orWindows8?•  VirtualAlloc()•  WriteProcessMemory()•  VirtualProtect()•  NtSetInformaMonProcess()

Page 35: recon / OSINT [Open Source Intelligence]Oxford Handbook of Naonal Security Intelligence The Tao of Open Source Intelligence Infosec InsMtute osinuramework.com owasp.org digital-forensics.sans.org

Thankyou!

[email protected]